Executive brief
Oracle Access Manager, a critical component for managing user identities and controlling access to corporate applications, contains a vulnerability in its authentication engine. An unauthorized attacker can exploit this over the network to gain access to sensitive data managed by the system. Because this tool acts as a gateway for other services, a successful attack could also compromise additional connected business products and data.
Technical details
A vulnerability exists in the Authentication Engine component of Oracle Access Manager (part of Oracle Fusion Middleware). The flaw is categorized by a CVSS 3.1 score of 8.6, primarily due to a high confidentiality impact and a scope change (S:C), meaning the exploit can impact resources beyond the immediate security scope of the component. An unauthenticated attacker can exploit this vulnerability remotely via HTTP without user interaction. Successful exploitation allows for unauthorized access to critical data or complete access to all data accessible by Oracle Access Manager. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Access Manager 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory